index=msad | eval reformattedDomain = replace(replace(questionname,"\(\d+\)","."),"\.(.*)\.","\1")
|stats count by reformattedDomain
|lookup malware_domainsdm.csv domain AS reformattedDomain
| eval domainmatch=if(reformatedDomain==domain, "bad", "good")
This gets me closer but I am having trouble populating the other malwaredomaindm.csv fields like category, date, and reference. Any ideas?
Thank you
... View more